VMware vCenter Syslog flaw exploited at scale and by ransomware (CVE-2026-59310)
Attackers began exploiting CVE-2026-59310, a critical unauthenticated remote code execution flaw in the VMware vCenter Syslog server, days after Broadcom patched it, compromising more than 360 systems in 47 countries; CISA later flagged the bug as used in ransomware campaigns.
- Victim
- VMware vCenter Server (Broadcom)
On 13 August 2026, researchers reported that attackers were mass-exploiting CVE-2026-59310, a critical vulnerability in the Syslog server of VMware vCenter, Broadcom's central management platform for vSphere virtual infrastructure. The flaw is a directory traversal issue (CWE-22) rated CVSS 9.8 that lets an unauthenticated attacker with network access to vCenter execute arbitrary code. Broadcom had disclosed and patched it on 29 July 2026.
What happened
According to incident responders at QUIRSO, compromised systems began contacting attacker infrastructure on 3 August, only five days after the advisory. The campaign grew quickly: 151 new victim IP addresses appeared on 4 August, the count reached 343 the next day, and by 7 August researchers had identified 361 victim IPs across 47 countries, with Germany, the United States, Turkey, Iran and France accounting for more than half. The attackers installed the open-source reverse_ssh framework to open outbound command-and-control channels that bypass inbound firewall rules. QUIRSO attributed the activity to an advanced persistent threat actor but withheld indicators, citing coordination with law enforcement.
On 18 August, CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave U.S. federal civilian agencies until 21 August to apply mitigations. By mid-September, the agency's catalog entry flagged the vulnerability as known to be used in ransomware campaigns, and Shadowserver was still tracking more than 450 internet-exposed vCenter servers. Fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f.
Why it matters
vCenter controls every host and virtual machine in a vSphere environment, so a pre-authentication code execution bug gives an intruder a direct path to the hypervisor layer that ransomware operators target to encrypt entire server estates at once. The short gap between patch and mass exploitation, and the later move to ransomware use, repeat a pattern seen with earlier VMware flaws: CISA has tagged 26 VMware vulnerabilities as exploited over the past five years, nine of them by ransomware gangs.
Timeline
Broadcom discloses and patches CVE-2026-59310, a critical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8.
Compromised vCenter systems start connecting to attacker-controlled infrastructure, five days after the patch.
Researchers at QUIRSO count 361 victim IP addresses across 47 countries.
Exploitation is publicly reported, with attackers deploying the reverse_ssh framework for persistent remote access.
CISA adds CVE-2026-59310 to its Known Exploited Vulnerabilities catalog with a 21 August deadline for federal agencies.
CISA's catalog now marks the flaw as known to be used in ransomware campaigns.
Sources
- support.broadcom.comhttps://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017
- cisa.govhttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-59310
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-59310
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/critical-vmware-vcenter-rce-flaw-exploited-for-reverse-ssh-access/
- securityweek.comhttps://www.securityweek.com/critical-vmware-vcenter-vulnerability-in-attackers-crosshairs/
- bleepingcomputer.comhttps://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/